<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA Reachable but the equipment's connected to it are not in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-reachable-but-the-equipment-s-connected-to-it-are-not/m-p/4976502#M1106815</link>
    <description>&lt;P&gt;Hi Guys ,&lt;/P&gt;&lt;P&gt;I have a sort of a confusing issue so basically I'm trying to connect an ASA 5506-X(remote site ) to our DC via site to site VPN when connecting the device i notice that the VPN tunnel is up and from our mgmt vm's i can ping the remote asa fw how ever i cannot ping any of my equipment's that are connected&amp;nbsp; it .&lt;/P&gt;&lt;P&gt;What's really confusing for me is even tho we work with basic settings (no NAT..) and every time deploying a new site we use the same config almost and it always works perfectly i started to think that maybe the asa is faulty since it's a used one but not sure.&lt;/P&gt;&lt;P&gt;What do u guys think ? I'm getting hard time troubleshooting this issue .&lt;/P&gt;&lt;P&gt;the full config is in the attachment&lt;/P&gt;</description>
    <pubDate>Tue, 12 Dec 2023 20:07:10 GMT</pubDate>
    <dc:creator>rahaliix131005</dc:creator>
    <dc:date>2023-12-12T20:07:10Z</dc:date>
    <item>
      <title>ASA Reachable but the equipment's connected to it are not</title>
      <link>https://community.cisco.com/t5/network-security/asa-reachable-but-the-equipment-s-connected-to-it-are-not/m-p/4976502#M1106815</link>
      <description>&lt;P&gt;Hi Guys ,&lt;/P&gt;&lt;P&gt;I have a sort of a confusing issue so basically I'm trying to connect an ASA 5506-X(remote site ) to our DC via site to site VPN when connecting the device i notice that the VPN tunnel is up and from our mgmt vm's i can ping the remote asa fw how ever i cannot ping any of my equipment's that are connected&amp;nbsp; it .&lt;/P&gt;&lt;P&gt;What's really confusing for me is even tho we work with basic settings (no NAT..) and every time deploying a new site we use the same config almost and it always works perfectly i started to think that maybe the asa is faulty since it's a used one but not sure.&lt;/P&gt;&lt;P&gt;What do u guys think ? I'm getting hard time troubleshooting this issue .&lt;/P&gt;&lt;P&gt;the full config is in the attachment&lt;/P&gt;</description>
      <pubDate>Tue, 12 Dec 2023 20:07:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-reachable-but-the-equipment-s-connected-to-it-are-not/m-p/4976502#M1106815</guid>
      <dc:creator>rahaliix131005</dc:creator>
      <dc:date>2023-12-12T20:07:10Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Reachable but the equipment's connected to it are not</title>
      <link>https://community.cisco.com/t5/network-security/asa-reachable-but-the-equipment-s-connected-to-it-are-not/m-p/4976505#M1106816</link>
      <description>&lt;P&gt;Do this command&amp;nbsp;&lt;/P&gt;
&lt;P&gt;clear crypto ipsec sa inactive&lt;/P&gt;
&lt;P&gt;Then check again&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Dec 2023 20:11:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-reachable-but-the-equipment-s-connected-to-it-are-not/m-p/4976505#M1106816</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-12-12T20:11:51Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Reachable but the equipment's connected to it are not</title>
      <link>https://community.cisco.com/t5/network-security/asa-reachable-but-the-equipment-s-connected-to-it-are-not/m-p/4976508#M1106817</link>
      <description>&lt;P&gt;on the remote FW right, I'll definetly try it&amp;nbsp;&lt;/P&gt;&lt;P&gt;appreciated&lt;/P&gt;</description>
      <pubDate>Tue, 12 Dec 2023 20:26:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-reachable-but-the-equipment-s-connected-to-it-are-not/m-p/4976508#M1106817</guid>
      <dc:creator>rahaliix131005</dc:creator>
      <dc:date>2023-12-12T20:26:39Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Reachable but the equipment's connected to it are not</title>
      <link>https://community.cisco.com/t5/network-security/asa-reachable-but-the-equipment-s-connected-to-it-are-not/m-p/4976511#M1106818</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1150739"&gt;@rahaliix131005&lt;/a&gt; if the tunnel is up, are the encap|decap counters increasing or not? Run "show crypto ipsec sa" on both sides and confirm, provide the output for review.&lt;/P&gt;
&lt;P&gt;If the counters are increasing on one side but not the other, then that usually indicates a NAT or a routing issue.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Dec 2023 20:39:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-reachable-but-the-equipment-s-connected-to-it-are-not/m-p/4976511#M1106818</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2023-12-12T20:39:05Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Reachable but the equipment's connected to it are not</title>
      <link>https://community.cisco.com/t5/network-security/asa-reachable-but-the-equipment-s-connected-to-it-are-not/m-p/4976513#M1106819</link>
      <description>&lt;P&gt;I'm aware of the command u mentioned before but can you please explain the e&lt;SPAN&gt;ncap|decap counters ? , and for routing we just use static routes , nothing fancy . we always work with the same config same FW but this one is just not working properly&amp;nbsp;&amp;nbsp;pretty weird&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Dec 2023 20:46:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-reachable-but-the-equipment-s-connected-to-it-are-not/m-p/4976513#M1106819</guid>
      <dc:creator>rahaliix131005</dc:creator>
      <dc:date>2023-12-12T20:46:06Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Reachable but the equipment's connected to it are not</title>
      <link>https://community.cisco.com/t5/network-security/asa-reachable-but-the-equipment-s-connected-to-it-are-not/m-p/4976516#M1106820</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1150739"&gt;@rahaliix131005&lt;/a&gt; for example: If the decaps counter is increasing then encrypted traffic is received, but if the encaps counter does not increase then the return traffic is not encrypted. This could either because traffic behind the ASA is not routing to the ASA (and vice versa) or more commonly there is no NAT exemption rule, so the return traffic is unintentially translated behind the firewall's outside interface. Another common issue is there is a local host based firewall on the client devices and traffic is dropped (hence no return traffic).&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="RobIngram_0-1702414139383.png" style="width: 540px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/204795iA0529B1026CD2FEE/image-dimensions/540x212?v=v2" width="540" height="212" role="button" title="RobIngram_0-1702414139383.png" alt="RobIngram_0-1702414139383.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Dec 2023 20:52:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-reachable-but-the-equipment-s-connected-to-it-are-not/m-p/4976516#M1106820</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2023-12-12T20:52:22Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Reachable but the equipment's connected to it are not</title>
      <link>https://community.cisco.com/t5/network-security/asa-reachable-but-the-equipment-s-connected-to-it-are-not/m-p/4976549#M1106824</link>
      <description>&lt;P&gt;You have only provided configuration for one side of the site to site VPN setup which makes it hard to see if there is anything missing or faulty in the configuration.&lt;/P&gt;
&lt;P&gt;Assuming that all configuration on the DC side of the VPN is correct (No-NAT, crypto ACL, routing, etc.) then the most likely issue is routing / default gateway configuration on the endpoints or the network in between that you are trying to reach.&lt;/P&gt;
&lt;P&gt;Another thing you could do is a packet tracer on the ASA5506 with a source of an inside / local IP and destination remote IP you are testing from to verify that the traffic truly is being sent into the tunnel. Run the packet-tracer twice and post the results here.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Dec 2023 22:00:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-reachable-but-the-equipment-s-connected-to-it-are-not/m-p/4976549#M1106824</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2023-12-12T22:00:25Z</dc:date>
    </item>
  </channel>
</rss>

